#PSIRT
Recapping Fortinet's spectacular Patch Tuesday:

-bypass auth using serial number: fortiguard.fortinet.com/psirt/FG-IR-...
-forge cookies to bypass auth: pwner.gg/blog/2025-08...
-bug with exploit in the wild: www.fortiguard.com/psirt/FG-IR-...

And I thought my day was rough yesterday... sheeeeesh!
August 13, 2025 at 9:59 PM
Fortinet is a serious security company guys just LOOK at all the scary IOCs www.fortiguard.com/psirt/FG-IR-...
January 16, 2025 at 8:27 AM
New Fortinet zero-day on Easter eve... precious timing

fortiguard.fortinet.com/psirt/FG-IR-...
April 5, 2026 at 5:33 PM
In other news, I can intro hiring managers to at least 3 great security program, product, or project managers, including one with PSIRT experience.

2/
May 15, 2025 at 3:08 PM
Attention!

Check your Compromised Website Report for critical events tagged “fortinet-compromised” and follow Fortinet's mitigation advice on compromised devices:

fortinet.com/blog/psirt-b...

Data available from 2025-04-11+

shadowserver.org/what-we-do/n...
April 12, 2025 at 12:15 PM
Has anyone considered that maybe Fortinet is a really long-running practical joke? fortiguard.fortinet....
PSIRT | FortiGuard Labs
None
fortiguard.fortinet.com
November 18, 2025 at 8:19 PM
A new SonicWall zero-day (CVE-2025-23006):

psirt.global.sonicwall.com/vuln-detail/...

"SonicWall PSIRT has been notified of possible active exploitation of the referenced vulnerability by threat actors."
Security Advisory
psirt.global.sonicwall.com
January 23, 2025 at 5:52 PM
I've added a Cisco PSIRT AI Agent to the mix

Now I can ask

"Is R1 vulnerable?"

More to come
February 22, 2025 at 5:31 PM
📋 Daily security briefing — 2026-09-22

267 CERT/PSIRT advisories · 5930 CVEs · 4 added to CISA KEV (actively exploited)

https://www.csirts.com/briefing/2026-09-22
September 23, 2026 at 6:29 PM
Fortinet fixes a critical FortiOS vulnerability exploited in the wild and 28
other vulnerabilities
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 9.6
PSIRT | FortiGuard Labs
None
www.fortiguard.com
January 15, 2025 at 5:12 AM
🔐 EU's Cyber Resilience Act is coming. Open source projects need:

-5-year security roadmaps
-PSIRT teams
-Security policies

Get the full insights in our report: www.linuxfoundation.org/research/cra...

#OpenSource #CRA #EUregulation
April 21, 2025 at 1:29 PM
We added Fortinet SSL-VPN CVE-2020-12812 to our daily Vulnerable HTTP Report: www.shadowserver.org/what-we-do/n...

After 5 1/2 years since being published still over 10K Fortinet firewalls remain unpatched. Actively exploited as recently highlighted by Fortinet: www.fortinet.com/blog/psirt-b...
January 2, 2026 at 11:10 AM
📋 Daily security briefing — 2026-09-21

219 CERT/PSIRT advisories · 3797 CVEs · 1 added to CISA KEV (actively exploited)

https://www.csirts.com/briefing/2026-09-21
September 22, 2026 at 6:10 PM
ひさびさ(2年ぶりくらい?)に寄稿しました (freee PSIRT連載の最終回)https://twitter.com/gihyosd/status/1824605663005430232
August 17, 2024 at 12:46 PM
FortiOS: LDAP authentication bypass in Agentless VPN and FSSO
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.5
PSIRT | FortiGuard Labs
None
www.fortiguard.com
February 11, 2026 at 7:27 AM
📋 Daily security briefing — 2026-09-20

1 CERT/PSIRT advisories · 104 CVEs

https://www.csirts.com/briefing/2026-09-20
September 21, 2026 at 8:01 AM
Oh is it time for another Fortinet crit again? Unauthenticated admin password change in FortiSwitch.

CVE-2024-48887, CVSSv3 9.3

fortiguard.fortinet....

#CVE #ThreatIntel
PSIRT | FortiGuard Labs
None
fortiguard.fortinet.com
April 9, 2025 at 6:33 AM
Arctic Wolf says threat actors are using a new Fortinet zero-day to mass compromise of Fortinet FortiGate firewalls arcticwolf.com/resources/bl...

A patch is here: fortiguard.fortinet.com/psirt/FG-IR-...
Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls - Arctic Wolf
Arctic Wolf Labs identified a campaign targeting Fortinet FortiGate firewall devices with exposed management interfaces.
arcticwolf.com
January 15, 2025 at 11:26 AM
Critical Path Traversal Vulnerability Identified in Fortinet FortiWLM
URL: www.fortiguard.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8
PSIRT | FortiGuard Labs
None
www.fortiguard.com
December 19, 2024 at 5:53 AM
Fortinet: Multiple Products' FortiCloud SSO Login Authentication Bypass
URL: fortiguard.fortinet.com/psirt/FG-IR-...
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.1
PSIRT | FortiGuard Labs
None
fortiguard.fortinet.com
December 10, 2025 at 6:45 AM
📋 Daily security briefing — 2026-09-19

1 CERT/PSIRT advisories · 129 CVEs

https://www.csirts.com/briefing/2026-09-19
September 20, 2026 at 5:32 PM
Fortinet has urged customers to install a recent FortiGate firmware update that mitigates a new technique abused in the wild.

The technique allows attackers to maintain read-only access to FortiGate devices they previously infected. (1/2)

www.fortinet.com/blog/psirt-b...
April 12, 2025 at 6:58 PM